Skip to content

Blackshades

Blackshades is a Windows-focused remote access trojan that emerged around 2010 and was widely sold on underground forums at low cost, contributing to large-scale global abuse.

Profile source: Mallory opens in a new tab

Blackshades

Family profile

Blackshades is a Windows-focused remote access trojan that emerged around 2010 and was widely sold on underground forums at low cost, contributing to large-scale global abuse. It enabled remote control of infected systems and was used to compromise and spy on hundreds of thousands of computers worldwide. Public reporting and law-enforcement actions have linked its development and sale to Alex Yücel and Michael Hogue.

Blackshades provides attackers with broad remote-administration and surveillance capabilities, including unauthorized access to victim machines, file access and modification, keystroke logging, webcam access, payload download and execution, and use of infected hosts as proxies. It has also been used to direct infected systems into distributed denial-of-service activity and has been described as capable of lock-screen style ransom behavior. Operators commonly paired it with obfuscation tools to reduce antivirus detection.

Distribution has been associated with malicious webpages, including drive-by download activity, as well as removable media such as USB devices. The malware was used both by opportunistic cybercriminals and in politically motivated surveillance. It was documented in campaigns targeting Syrian opposition figures, and it also figured in criminal sextortion cases involving covert webcam surveillance and theft of intimate material.

Blackshades became the subject of major international law-enforcement action, culminating in a 2014 coordinated crackdown spanning numerous countries and resulting in arrests, searches, and device seizures. Its history is frequently cited as a prominent example of a commodity RAT marketed as a purported administration tool but broadly used for unauthorized access, surveillance, and other criminal activity.

Capabilities

  • Ddos
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Post Exploitation
  • Spoofing

Reported operators

Threat actors

1 named in public reporting
Aluminum Saratoga

ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat

MITRE ATT&CK

Blackshades in ATT&CK

16 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.